There’s a reason I use Firefox (Gecko). Also, Ladybird—another completely different web engine—is really promising. I spent five hours building it from source, having it take about 8 gigabytes of space, and it perfectly renders my own webpages and blogs.
I have a feeling someone’s going to make an open source browser using Ladybird’s engine before Ladybird has official binaries.
The reason why I support Gecko and Ladybird’s engine is because I am opposed to monoculture, however. Even if Gecko (Firefox) is less secure than Chromium (Chrome, Edge, etc.), by not having a monoculture, a Chrome exploit will only take down the subset of people using the Chromium ecosystem, and not affect Gecko users. Alas, most people are in the Chromium ecosystem right now so that means malicious hackers only need to target one codebase.
It’s the same reason I wrote MaraDNS back in 2001—back then, there was only one open source DNS server[1,2] so I wrote another one.[3]
[1] Djbdns was around back then but wasn’t open source, which limited its adoption.
[2] MaraDNS was and is optimized for running at most a few dozen domains on a system running a bunch of other services, where one does not want the DNS server causing security problems for the server, and where the DNS server needs to be lightweight as possible.
you can, but it's better to use a different model or higher effort level at the very least to do the verifying part. (haven't checked to see what it is they are doing exactly), but doing vulnerability validation with the same model and effort you used to find the vulnerabilities isn't going to be a true second set of eyes and the model will likely always just try and justify it was right in the first place. ime, it's better to start with a fresh, clean context and at the very least a higher effort level on the same model. pass the finding(s) to a model that hasn't seen it before and it will judge it with an unbiased perspective.
How so? I tend to disagree with the general statement that this is common in the infosec world, but I'd like to understand better what you mean by that.
Impact in this case, is non-existent (Wow they got my email)
> I'd like to understand better what you mean by that.
Recall there was a period where every CPU sidechannel attack had a dedicated (wow) website and a rock band name assigned to it (when in reality their impact again, was/is limited).
reply